Regulatory compliance

NIS2, DORA, ISO standards and GDPR in a single compliance path, with audit-ready evidence.

The challenge

Regulations overlap: the same measure serves NIS2, ISO/IEC 27001 and GDPR, yet it is often handled three times by three different people. We bring every regulation that applies to you into a single path — assessment, plan, implementation, evidence — so each effort counts for several obligations and the audit finds the proof ready.

NIS2 — Network and information systems security

The NIS2 directive, transposed in Italy by Legislative Decree 138/2024, extends security obligations to thousands of companies — essential and important entities — and also involves their suppliers and management bodies. We check whether and how it applies to you, measure the gap on the required measures and hand you a plan ordered by risk, not by chapter of the regulation.

  • Applicability assessment and entity classification
  • Gap analysis on the required security measures
  • Incident handling and notification procedures
  • Training for management bodies and staff

DORA — Digital operational resilience

For banks, insurers, financial intermediaries and their ICT suppliers, Regulation (EU) 2022/2554 requires proof that you can keep operating when something breaks. We map critical services and third-party dependencies, define the testing plan and align supplier contracts.

  • Map of critical services and third-party dependencies
  • Register of information on ICT suppliers
  • Operational resilience testing plan
  • Contract clauses to add with suppliers

ISO/IEC 27001 — Information security

We build the information security management system around the processes you actually have and guide you up to the certification audit: a system that lasts, not a binder written just to pass the exam.

  • Scope, risk assessment and statement of applicability
  • Policies and procedures built on real processes
  • Internal audits, management review and support at the certification body's audit

ISO 9001 — Quality

Clear processes, defined responsibilities and measurable continuous improvement: we set up the quality management system and prepare you for the certification body's audit.

ISO 22301 — Business continuity

Impact analysis, continuity strategies and recovery plans tested in the field: to keep operating even when a system, a supplier or a site goes down.

ISO/IEC 20000-1 — IT service management

For those delivering IT services to internal or external customers: request, incident, change and service level management processes aligned with the standard, and measured.

ISO/IEC 42001 — Artificial intelligence

To use or develop artificial intelligence in a governed way: roles, risk assessment and controls according to the international standard for AI management systems.

GDPR — Personal data protection

From the processing register to ready answers when a data subject actually writes in: we rebuild the processing map around how you work today and leave procedures your team can carry out on its own.

  • Processing register, privacy notices and legal bases
  • Appointments and agreements with providers processing data on your behalf
  • Procedures for data-subject requests and personal data breaches

What we deliver

  • Map of the applicable regulations and of your compliance level
  • Gap analysis with collected evidence and a remediation plan with priorities, timelines and owners
  • Policies, procedures and registers built around your real processes
  • Support during audits and authority inspections
  • Training for staff and management bodies